Integrate Your AssetsSaaS

Secure NextDNS with Mondoo

Continuously scan your NextDNS profiles for misconfigurations and security issues.

Mondoo continuously scans your NextDNS profiles for misconfigurations and security issues. Create a NextDNS integration to give Mondoo access to your NextDNS account.

Mondoo discovers every profile in the NextDNS account and adds each one as a NextDNS Profile asset. For each profile, Mondoo assesses threat protection (such as threat intelligence feeds, Google Safe Browsing, DNS rebinding protection, and blocking of newly registered domains), block-bypass protection, and query-logging settings.

Prerequisites

  • Editor or Owner access to the Mondoo space
  • A NextDNS account with one or more profiles

Find your NextDNS API key

Mondoo authenticates to NextDNS with your account's API key.

  1. Sign in to your NextDNS account page.

  2. Scroll to the API section at the bottom of the page.

  3. Copy the API key.

NextDNS API keys don't have scopes: the key grants access to every profile in the account. Mondoo only reads profile configuration and never changes it.

Treat the API key like a password. Don't commit it to source control. If the key is exposed, regenerate it on the NextDNS account page and update the integration.

Add a NextDNS integration

Only team members with Editor or Owner access can perform this task.

In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:

  1. Under SaaS Security, select NextDNS.

    Add a NextDNS integration in Mondoo

  2. In the Choose an integration name box, enter a name that identifies the NextDNS account.

  3. Paste the API key into the Provide your NextDNS API key box.

  4. (Optional) Under Enable security policies, review the policies that apply to NextDNS. The Mondoo NextDNS Security policy checks threat protection, filtering integrity, and query logging. If a policy isn't enabled in the space yet, select ENABLE. A policy you enable here applies to the whole space, not only this integration.

  5. Select CREATE INTEGRATION.

Mondoo starts the first scan as soon as the integration is created. To learn how policies work, read Manage Policies.

View results

Mondoo adds a NextDNS Profile asset for each profile to the space inventory. To review them, navigate to the space and select Inventory > Assets. To see how the profiles score against the policy, select Findings > Policies and choose Mondoo NextDNS Security.

Manage your integration

To open the integration, navigate to the space, select Integrations > NextDNS, and choose the integration.

From the integration detail page, you can:

  • Scan now. Select RUN.
  • Pause or resume scanning. Select the more actions menu, then Pause or Resume.
  • Edit settings. Select the pencil icon to rename the integration or replace its API key. Leave the key box empty to keep the existing key.
  • Remove the integration. Select the trash can icon and confirm. Mondoo stops scanning the NextDNS account.

Scan NextDNS from the command line

The integration scans continuously from the Mondoo Platform. To scan NextDNS from your workstation or a CI pipeline instead, see Secure NextDNS with cnspec.

Next steps

On this page